Описание
Security update for libsoup
This update for libsoup fixes the following issues:
- CVE-2026-85197: heap use-after-free in HTTP/2
client on_data_read()viaGOAWAYduring body upload (bsc#1279238). - CVE-2026-85534: heap buffer overflow in
SoupSessionthroughon_data_source_read_callback()viaSETTINGSframe with craftedINITIAL_WINDOW_SIZE(bsc#1279239).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1279238
- SUSE Bug 1279239
- SUSE CVE CVE-2026-85197 page
- SUSE CVE CVE-2026-85534 page
Описание
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
Затронутые продукты
Ссылки
- CVE-2026-85197
- SUSE Bug 1279238
Описание
A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.
Затронутые продукты
Ссылки
- CVE-2026-85534
- SUSE Bug 1279239